The posting, in Replit's own words
archived Sep 11, 2026Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the Team
Product Platform builds and owns the shared foundations the rest of Replit is built on, spanning the full stack so every other team can ship features safely and quickly. Identity & Authorization defines how people, agents, sandboxes, and services prove who they are and what they can do. These systems protect critical product and service interactions across Replit's web product, Agent, enterprise controls, and internal services. Our work is high-leverage and horizontal: when identity and policy are clear, reliable, and easy to adopt, every other team can move faster without rebuilding security controls. We are a small, collaborative team that values curiosity and clear thinking over pedigree, and we work in the open by bringing each other the problem rather than just the request. We care more about how you reason and build than the route you took to get here.
Read the full posting ↓
About the Role
As a Software Engineer , you will design, build, and operate the identity and authorization systems that protect critical interactions on Replit, including Agent acting on behalf of a user or holding their own identity.
The work is guided by a few simple questions:
Can every protected request prove which workload made it, which principal it represents, and who is acting on that principal's behalf? Can product teams express policy once and trust the same decision across web, mobile, Agent, and internal services? Can enterprise administrators control who can access each workspace, app, connector, and Agent capability without navigating a permission maze as well as having a legible ledger of decisions? Can Agent act for a user across long-running and durable work without receiving broad or long-lived credentials? Are identity and authorization fast, reliable, highly available, and observable enough for the product flows that depend on them?